1
1

00:00:01,350  -->  00:00:03,270
<v Instructor>Permissions audits.</v>
2

2

00:00:03,270  -->  00:00:05,880
In this lesson, I'm going to show you how we perform
3

3

00:00:05,880  -->  00:00:07,800
account and permission audits,
4

4

00:00:07,800  -->  00:00:10,500
and we're going to jump into the lab environment to do this.
5

5

00:00:10,500  -->  00:00:11,970
As I do this, we're going to be using
6

6

00:00:11,970  -->  00:00:15,360
one of my Windows Domain Controllers that I built in my lab.
7

7

00:00:15,360  -->  00:00:16,410
The first thing we're going to do
8

8

00:00:16,410  -->  00:00:19,410
is we're going to open up the server manager.
9

9

00:00:19,410  -->  00:00:21,210
Once we're inside the server manager,
10

10

00:00:21,210  -->  00:00:23,250
we're going to go into the active directory,
11

11

00:00:23,250  -->  00:00:24,573
users and computers.
12

12

00:00:25,710  -->  00:00:27,330
From here, we're going to expand
13

13

00:00:27,330  -->  00:00:31,395
the corp.515support.com domain and select the audit
14

14

00:00:31,395  -->  00:00:32,583
OU container.
15

15

00:00:34,140  -->  00:00:35,280
Now in this example,
16

16

00:00:35,280  -->  00:00:36,360
what I'm going to do is pretend
17

17

00:00:36,360  -->  00:00:38,250
that my company is being audited.
18

18

00:00:38,250  -->  00:00:39,390
So I'm going to have several people
19

19

00:00:39,390  -->  00:00:41,460
who are going to come in to perform an audit.
20

20

00:00:41,460  -->  00:00:43,200
These are going to be people like Anthony Stevens,
21

21

00:00:43,200  -->  00:00:45,210
Catherine Ruiz, Douglas Price,
22

22

00:00:45,210  -->  00:00:47,130
Irene Taylor, and Luke Packard.
23

23

00:00:47,130  -->  00:00:48,930
All of them should have received a user account
24

24

00:00:48,930  -->  00:00:51,210
and then placed in the audit OU container.
25

25

00:00:51,210  -->  00:00:52,043
Now when I look here,
26

26

00:00:52,043  -->  00:00:54,090
I only see that four of those people are there.
27

27

00:00:54,090  -->  00:00:55,890
I'm missing Anthony Stevens.
28

28

00:00:55,890  -->  00:00:57,360
So we're going to want to go ahead
29

29

00:00:57,360  -->  00:00:59,760
and find Anthony Stevens and put him in this OU
30

30

00:00:59,760  -->  00:01:01,920
and then verify he has the right permissions.
31

31

00:01:01,920  -->  00:01:03,240
To do this, we're going to right click
32

32

00:01:03,240  -->  00:01:06,960
on corp.515support.com and select find.
33

33

00:01:06,960  -->  00:01:07,860
From here we can type
34

34

00:01:07,860  -->  00:01:11,220
in the user's name, Anthony Stevens, and click find now.
35

35

00:01:11,220  -->  00:01:12,780
Once we find him in the search results,
36

36

00:01:12,780  -->  00:01:14,940
we can right click that account, select move,
37

37

00:01:14,940  -->  00:01:16,500
and select the appropriate container.
38

38

00:01:16,500  -->  00:01:19,770
In this case, AuditOU and click okay.
39

39

00:01:19,770  -->  00:01:22,590
At this point, we can close the find dialogue box.
40

40

00:01:22,590  -->  00:01:24,810
Now we don't see his name in this pane yet,
41

41

00:01:24,810  -->  00:01:26,520
and that's because we haven't refreshed it.
42

42

00:01:26,520  -->  00:01:29,100
So let's right click in the pane and select refresh.
43

43

00:01:29,100  -->  00:01:31,260
Now we see Anthony Stevens.
44

44

00:01:31,260  -->  00:01:33,540
Let's go ahead and verify his permissions are correct.
45

45

00:01:33,540  -->  00:01:34,980
We'll right click on Anthony Stevens
46

46

00:01:34,980  -->  00:01:36,570
and click on properties.
47

47

00:01:36,570  -->  00:01:37,650
Once we're in properties,
48

48

00:01:37,650  -->  00:01:39,840
we're going to select the account tab.
49

49

00:01:39,840  -->  00:01:42,030
Here, under account options, we want to verify
50

50

00:01:42,030  -->  00:01:44,850
that the user must change password at next logon is selected
51

51

00:01:44,850  -->  00:01:46,620
because we gave him a temporary password
52

52

00:01:46,620  -->  00:01:49,350
of password for him to log in the first time.
53

53

00:01:49,350  -->  00:01:52,200
And then we want to select the password never expires option
54

54

00:01:52,200  -->  00:01:53,880
and ensure it's unchecked.
55

55

00:01:53,880  -->  00:01:55,620
That way he has to change his passwords
56

56

00:01:55,620  -->  00:01:57,900
in accordance with our policies.
57

57

00:01:57,900  -->  00:02:00,150
Now let's go ahead and take a look at our logon hours.
58

58

00:02:00,150  -->  00:02:01,980
Go ahead and click on logon hours.
59

59

00:02:01,980  -->  00:02:04,110
And from here we can see that this user is not
60

60

00:02:04,110  -->  00:02:06,360
able to access his accounts on the weekends.
61

61

00:02:06,360  -->  00:02:09,150
Now this table is going to show us a 24-hour day
62

62

00:02:09,150  -->  00:02:11,430
and any white cells are deny access
63

63

00:02:11,430  -->  00:02:14,010
and any blue cells means to allow access.
64

64

00:02:14,010  -->  00:02:16,170
Because he's going to be working Monday through Friday,
65

65

00:02:16,170  -->  00:02:17,310
he should only be able to use it
66

66

00:02:17,310  -->  00:02:20,520
during those working hours and not during the weekends.
67

67

00:02:20,520  -->  00:02:21,510
So at this point, we're going to go ahead
68

68

00:02:21,510  -->  00:02:23,280
and click cancel and then we're going to click
69

69

00:02:23,280  -->  00:02:25,110
log on to button.
70

70

00:02:25,110  -->  00:02:28,080
In the logon workstation's dialogue box, we can verify
71

71

00:02:28,080  -->  00:02:31,860
that he's only able to log on to audit-alpha computer.
72

72

00:02:31,860  -->  00:02:33,240
This means that this auditor
73

73

00:02:33,240  -->  00:02:35,130
has one machine he's assigned to,
74

74

00:02:35,130  -->  00:02:36,510
and this can help us verify
75

75

00:02:36,510  -->  00:02:38,370
since we're giving auditors special permissions
76

76

00:02:38,370  -->  00:02:40,380
that they can't do it on any other systems,
77

77

00:02:40,380  -->  00:02:41,970
or if their account is compromised,
78

78

00:02:41,970  -->  00:02:43,860
they can minimize the damage.
79

79

00:02:43,860  -->  00:02:46,140
From here, let's take a look at the member of tab
80

80

00:02:46,140  -->  00:02:49,200
to see what groups Anthony Stevens belongs to.
81

81

00:02:49,200  -->  00:02:50,160
Now, as we look at this,
82

82

00:02:50,160  -->  00:02:52,050
is there anything that looks abnormal?
83

83

00:02:52,050  -->  00:02:54,660
Well, yeah, it shows that he's a domain admin.
84

84

00:02:54,660  -->  00:02:56,940
That is a big security risk.
85

85

00:02:56,940  -->  00:02:59,130
So we want to go into the domain admin,
86

86

00:02:59,130  -->  00:03:02,190
click on that in the member of list, and then remove it.
87

87

00:03:02,190  -->  00:03:04,560
At this point, we'll confirm it by saying yes,
88

88

00:03:04,560  -->  00:03:06,090
and then we can click the add button
89

89

00:03:06,090  -->  00:03:07,740
and select the right group for him,
90

90

00:03:07,740  -->  00:03:11,610
which in our case is sec-glo-audit,
91

91

00:03:11,610  -->  00:03:13,470
which is going to be for our auditors who are
92

92

00:03:13,470  -->  00:03:15,990
performing their audits here this week.
93

93

00:03:15,990  -->  00:03:18,450
Now at this point, Anthony's account is all good.
94

94

00:03:18,450  -->  00:03:19,500
We've looked through the permissions,
95

95

00:03:19,500  -->  00:03:20,730
we've checked the logon times,
96

96

00:03:20,730  -->  00:03:22,530
and we made sure he is a member of the right groups.
97

97

00:03:22,530  -->  00:03:24,210
And now we would go through and do the same thing
98

98

00:03:24,210  -->  00:03:27,063
for Catherine, Douglas, Irene, and Luke.
99

99

00:03:29,700  -->  00:03:31,800
Once we're done looking through all of their accounts,
100

100

00:03:31,800  -->  00:03:33,900
we can then move on to our next section.
101

101

00:03:33,900  -->  00:03:34,980
And our next thing we're going to look
102

102

00:03:34,980  -->  00:03:37,680
at is any other IAM issues we may have.
103

103

00:03:37,680  -->  00:03:39,690
One of the big ones is making sure that we go
104

104

00:03:39,690  -->  00:03:41,520
through our accounts and make sure that any accounts
105

105

00:03:41,520  -->  00:03:44,940
on the domain are cleaned up according to our policy.
106

106

00:03:44,940  -->  00:03:47,700
For example, we might want to go into the user's container
107

107

00:03:47,700  -->  00:03:50,220
and then select view filter options.
108

108

00:03:50,220  -->  00:03:52,500
From here, we can select the following types of objects
109

109

00:03:52,500  -->  00:03:55,680
radio button, and check users and hit okay.
110

110

00:03:55,680  -->  00:03:58,920
Now we can see all the users on this system.
111

111

00:03:58,920  -->  00:04:01,350
For example, here in the users, you can see two
112

112

00:04:01,350  -->  00:04:03,750
accounts that are actually not supposed to be there.
113

113

00:04:03,750  -->  00:04:05,700
For example, you see the guest account,
114

114

00:04:05,700  -->  00:04:06,900
you should right click on this
115

115

00:04:06,900  -->  00:04:09,660
and disable that because it could be used by attackers.
116

116

00:04:09,660  -->  00:04:12,090
The other one I like to disable is administrator.
117

117

00:04:12,090  -->  00:04:13,710
Instead of using the administrator account
118

118

00:04:13,710  -->  00:04:15,150
using the word administrator,
119

119

00:04:15,150  -->  00:04:16,830
you should select something that isn't
120

120

00:04:16,830  -->  00:04:18,660
as easily guessed by an attacker.
121

121

00:04:18,660  -->  00:04:20,760
Since the administrator account is a default built-in
122

122

00:04:20,760  -->  00:04:22,470
account on all window systems,
123

123

00:04:22,470  -->  00:04:23,940
attackers know to look for it.
124

124

00:04:23,940  -->  00:04:25,860
So instead, you should create another administrator
125

125

00:04:25,860  -->  00:04:27,870
account that's not named administrator
126

126

00:04:27,870  -->  00:04:30,020
and then disable the administrator account.
